allente.dk
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (6)
- cdn.optimizely.com×2
- www.googletagmanager.com×2
- logx.optimizely.com×1
- www.allente.fi×1
- www.allente.no×1
- www.allente.se×1
Social
DNS records live
- NS
-
- ns1.dnshost.net
- ns2.dnshost.net
- MX
-
- 10 allente-dk.mail.protection.outlook.com
- TXT
-
Show 6 TXT records
_76e0om7rqz54aurygyspfa5i54zod9z_gmwacftxkgucx8w38fquci0grecn5pha6dc950dc8a5b6d7c1dc0442d517fa94dc034897a0a4c80bd79955fd80afd1249b6fa560cc961cef311a9a666d1388fe2e046205b523e511efa55568f25b4fa41ed78bdabca04844e83cf856fad52bc97242886136876e30ef5a07ef51ae4c45e0b92398d00fc2957be4cf38e70ef6752ede3f94d5bef1f7762a83b61468a3f1
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 include:spf.mph1.com include:mail.zendesk.com include:amazonses.com include:_spf.intility.com include:spf.protection.outlook.com include:_spf.storm121.com include:spf.bedrock.lime-technologies.com ip4:69.169.230.92 ip4:69.169.230.93 ip4:88.131.105.128/25 ip4:94.246.101.0/26 -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:ndr2pmkn@ag.eu.dmarcadvisor.com;policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAoerKB9KoY4+UhScgNNdZFKE5Js4Zs8uFcr3rr+VRAYk3tBFdpi7GJ6XCr6FK3k2uxDUkXcqvguDEuB…
selectors probed - selector1:
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 147 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
no-referrer-when-downgrade- permissions-policy
accelerometer=(), autoplay=(self), camera=(), document-domain=(), encrypted-media=(self), fullscreen=(self), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(*), sync-xhr=(*), usb=(), xr-spatial-tracking=(self)- x-content-type-options
nosniff- content-security-policy
default-src https: wss: blob: data: 'self' 'unsafe-inline' 'unsafe-eval' code.jquery.com account.psplugin.com commondatastorage.googleapis.com omni.teleperformance.se static.hotjar.com bat.bing.com track.adform.net *.doubleclick.net www.googleadservices.com www.googletagmanager.com connect.facebook.net test-allentetest.lekane.net allente.lekane.net tango-churn.viasat.dk *.vo.msecnd.net assets.adobedtm.com dl.episerver.net canaldigital.d3.sc.omtrdc.net fast.canaldigital.demdex.net dpm.demdex.net cm.everesttech.net cd-static.telenorcdn.net canaldigital.demdex.net a4560576362315776.cdn.optimizely.com a4560576362315776.cdn-pci.optimizely.com *.optimizely.com optimizely.s3.amazonaws.com cdn-assets-prod.s3.amazonaws.com; frame-ancestors 'self' www.elkjop.no elkjop.no www.power.no power.no logon.canaldigital.com ssotest.api-canaldigital.com ssostage.api-canaldigital.com localhost app.optimizely.com www.viaplaysportnews.dk;- strict-transport-security
max-age=15552000; includeSubDomains; preload